
Setup and standards · Pro and up
Theo
Theo’s job is to find what the company has not set up yet in AWS and GitHub, and keep one setup plan, most important first.
On this page
What Theo does
- One setup plan of what to turn on or configure in AWS and GitHub, most important first
- What each setup step costs, and how he verifies it at the next check-in
- GitHub Actions pinned to commit SHAs and read-only workflow token permissions, on plans without Priya’s Actions audit
- Why a teammate cannot see something, and what to connect or approve
What you can ask
You ask Grant, and he brings in Theo for questions like these.
- “What should we set up first in AWS?”
- “Why can’t Liz see our costs?”
- “Are we following AWS’s security basics?”
- “What does turning on GuardDuty cost?”
What you get
First: turn on MFA for the root user (critical; no AWS charge, about 10 minutes; CIS 1.5). Then a multi-region CloudTrail trail (high; S3 storage, usually a few dollars a month). Cost Explorer could not be checked: the AWS connection does not include costs.
What Theo reads
- AWS security posture
- Repository context
- AWS costs
When Theo works
Every 30 days on Pro and when you ask Grant. On Studio and Enterprise, every 7 days.
What Theo may do
Read-only: reads the approved sources and keeps the setup plan. The setup itself is yours to do.
What Theo never does
- Change anything: setup is the company’s to do
- Say the company meets a standard


